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This paper shows that a classic metalogical framework, including all Boolean operators, can be used 
to support the development of a metric behavioural theory for Markov processes. Previously, only in- 
tuitionistic frameworks or frameworks without negation and logical implication have been developed 
to fulfill this task. The focus of this paper is on continuous Markovian logic (CML), a logic that char- 
acterizes stochastic bisimulation of Markov processes with an arbitrary measurable state space and 
continuous-time transitions. For a parameter e > interpreted as observational error, we introduce 
an e-parameterized metatheory for CML: we define the concepts of e-satisfiability and e-provability 
related by a sound and complete axiomatization and prove a series of "parameterized" metatheorems 
including decidability, weak completeness and finite model property. We also prove results regarding 
the relations between metalogical concepts defined for different parameters. Using this framework, 
we can characterize both the stochastic bisimulation relation and various observational preorders 
based on behavioural pseudometrics. The main contribution of this paper is proving that all these 
analyses can actually be done using a unified complete Boolean framework. This extends the state of 
the art in this field, since the related works only propose intuitionistic contexts that limit, for instance, 
the use of the Boolean logical implication. 



1 Introduction 

Stochastic models have successfully been used to describe the qualitative and quantitative behavior of 
systems in many natural and artificial domains. The problems addressed in this paper refer to the most 
general models of Markov processes, defined for arbitrary (analytic) state-spaces and continuous-time 
transitions, henceforth continuous Markov processes (CMPs); they subsume well-known models such 
as continuous-time Markov chains and labelled Markov processes and for this reason our work can be 
simply instantiated for these particular models. CMPs have been initially introduced by Desharnais and 
Panangaden in IIDP03II . In this paper, for technical reasons, we use the definition of CMPs proposed by 
the first two authors and CardelU in HCLMllaL which exploits an equivalence between the definitions 
of Harsanyi type spaces IIMV04I and a coalgebraic view of labelled Markov processes lidVR99i proved, 
for instance, by Doberkat in fDobOVI]. 

In this paper the class of CMPs define the semantics for Continuous Markovian Logic (CML) 
IICLMl la[ ICLMl fbl . This is a multimodal logic endowed with modalities Lr,Mr for r € Q"*", similar 
to the ones used by the Aumann system IIAum99L that approximates the transition rates. For instance, a 
process satisfies L,-(p if the rate of its transition from the initial state to a state satisfying cp is at least r. In 
BCLMllall it has been proved that this logic characterizes the stochastic bisimulation of CMPs. 

Despite the elegant theories supporting the concepts of stochastic and probabilistic bisimulations and 
their relation to logics |LS9r|, these concepts remain too strict for applications. In modelling, the values 
of the rates or probabilities are often approximated and consequently, one is interested to know whether 
two processes that differ by a small amount in real-valued parameters show similar (not necessarily 
identical) behaviours. In such cases, instead of a bisimulation relation, one needs a metric concept 
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to estimate the degree of similarity of two systems in terms of their behaviours. The metric theory for 
Markov processes was initiated by Desharnais et al. HP +0 41 and has been greatly developed and explored 
by van Breugel, Worrell and others ||vBW01[|vB+03i Similar notions have been proposed in literature 
for less general models. Bringing with them notions such as the point-wise simulation distance defined in 
IIJS90II for discrete probabilistic systems, and the discounted distances proposed in ||AHM03[ IAFS 09 1 for 
weighted systems, and of the quantified similarities of timed systems studied in IIMHP05II and ifTFLlOl 
(see also BThrllll for an overview). 

One way of defining these behavioural distances was proposed by Kozen IIKoz85i and consists in 
replacing the classic logical framework used to encode properties of processes with a non-classical real- 
valued framework that will interpret logical formulae as functional expressions mapping states to reals. 
In this way, we get a relaxation of the satisfiability relation which is replaced by a function that reports 
the "degree of satisfiability" between a Markov process and a logical property. This further induces a 
behavioural pseudometric on processes with the stochastic bisimulation as its kernel and measuring the 
distance between processes in terms of their behavioural similarity. Such formalisms have since been 
proposed for Markov systems by Desharnais, Panangaden and others llD-i-041 IPan09ll . 

It was hoped that these metrics would provide a quantitative alternative to logic, but this did not 
happen. One reason could originate in the fact that all this "metric reasoning" focused exclusively on 
the semantics of the logic while a syntactic or a metalogical counterpart did not develop until recently. 
Such a logical perspective on distance was proposed by the first two authors of this paper and Cardelli in 
BCLMllaL where it was emphasized that, in the context of a completely axiomatized logic, the semantic 
distance between Markovian processes implicitly induces, via Hausdorff metrics, a distance between 
logical properties that can be interpreted as a measure of provability for CML. On this line, BCLMIlal 
and IICLMllbl contain the open ideas of a research program that we have followed ever since. This 
research aims to understand the relation between the pseudometric space of Markov processes and the 
pseudometric space of logical formulae i.e., the relation between the measure of similarity for Markov 
processes and the measure of provability in a corresponding stochastic/probabilistic logic. Eventually, 
in l,LMP12al . the first two authors in collaboration with Prakash Panangaden have identified a metric 
analog of Stone duality that relates the two pseudometric spaces and in [LMP12b| we have studied how 
convergence in the open ball topologies induced by the two pseudometrics "agree to the limit". 

However, we have yet to clarify what the kernel of the distance between logical formulae is. It was 
shown in [LMP12b | that it is possible to have formulae at distance that are not logically equivalent, and 
we have characterized this kernel for some limited fragments of CML. But the full picture has not been 
yet achieved. One reason for this difficulty originates from the fact that we have no pure metalogical 
definition of this distance, as it is always implicitly obtained from the definition of the behavioural 
pseudometrics, hence it depends of the semantics. This is exactly what we achieve in this paper: a 
metalogical definition of the behavioural distance. 

This paper is a step forward in the process of understanding this distance from a logical perspective. 
We define a parameterized metatheory for CML, where the parameter e > is interpreted as an obser- 
vational error which allows us to express properties approximating the behavior of a given CMP. This 
metatheory consists in defining an s-semantics, i.e., s-satisfiability relation denoted |=e, and to develop 
a complete Hilbert-style axiomatization for a corresponding concept of e-provability , denoted hg. The 
classic semantics and provability relation of CML are, in this context, the 0-semantics and 0-proof theory. 

This parametric metatheory allows us to transfer logical properties between various semantics defined 
for different parameters. For instance, we can translate 0-satisfiability into e-satisfiability and reverse, or 
0-provability into e-provability and reverse using appropriate encodings. Exactly this allows one to see 
the behavioural pseudometrics from a logical perspective. We show that the distance between two CMPs 
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mi and m2 can, in fact, be defined by the infimum of the set of values e such that for any CML formula 
(p, rrii h (/> iff nij |=£ (p, where {i,]} - {1,2}. 

We develop the parametric metatheory as a classic metatheory and in addition to the sound-complete 
axiomatization we prove a series of metatheorems including an e-deduction theorem, a e-finite model 
property and some e-decidability results for CML. 

The major contribution of this paper consists in the fact that this entire development respects the 
classic Boolean restrictions. So fare all attempts of realizing Kozen's idea |Koz85 | and defining a quan- 
titative version of the satisfiability relation, have faced noticeable problems related to the treatment of 
negation. Often in the papers treating this argument, negation is either eliminated, restricted to atomic 
propositions or considered in a non-Boolean context BFGKIOI IFLTlOl IDLT081 . This restriction is an 
impediment for the use of classic reasoning. For instance in IIDLT08I1 . the definition of e-satisfiability 
contains the following rules defined for an arbitrary Markov process m: 

m \=E^(I> iff m (j) 

m \=e{a)s(p iff 0{m, We) >6-£ 

where 9{m, M) is the probability of a transition from m to a state in the set M. Observe that the rule for 
negation requires to transport information from "e-semantics" to "-e-semantics" and that it is obviously 
non-Boolean. For instance, in the case 9{m, E0|e) = 6 one can prove, using the previous rules, that for 
£ > we have 

m |=£ {a)s(p \^{a)s(p. 

In other words, the logic is inconsistent if it is interpreted in a Boolean context. 

In the light of this observation, one can see the real contribution of our paper. We show that it is 
possible to obtain the sought after behavioral distances and remain Boolean and classic to all logical 
levels. Of course, one can argue that an intuitionistic approach is as good for applications as the classic 
Boolean approach is, and we cannot argue against this. But we believe that for a deeper understanding 
of Markov processes and for providing a strong theoretical background for an approximation theory of 
Markov processes, a classic logical framework is more useful. In fact, in IILMP12all a special Boolean 
algebra (called Aumann algebra) is identified with operators that corresponds to CML and we proved 
Stone duality results between these algebras and Markov processes. This enforces our trust that the 
Boolean setting is the right one for studying properties of Markov processes. 

To summarize, the achievements of this work are as follows. 

• We develop a parameterized metatheory for continuous Markovian logic that extends the classic 
metatheory. The parameter can be interpreted as observational error. 

• We define the concept of e-satisfiability and identify for it an appropriate concept of e-provability 
with a sound and complete Hilbert-style axiomatization. 

• We prove that classic metatheorems about CML remain true in the parametric semantics. Such 
properties are the weak completeness, the finite model property and decidability. 

• We show that this parameterized metatheory can be used to define a behavioural pseudometric, 
which is a distance between CMPs that characterizes the similarity of two processes from the 
point of view of their behaviours. 

• We identify two behavioural orders that have, in the parametric semantics, similar logical interpre- 
tations to the bisimulation in the classic semantics. 

• This entire development is essentially Boolean. 
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2 Preliminary definitions 

In this section we introduce some basic notations and concepts used throughout this paper. 

For arbitrary sets M,N, we denote by 2^^ the powerset of M, by M^N their disjoint union and by 
[M N] the set of functions from M to N. 

Given a relation 9? c MxM, the 9t-closure of a setA'^c Mis the setA'^^ = {meM\3ne N,(n,m) e 3?}; 
we say that is 'K-closed iff A^** c A^. If X c 2^, then denotes the set of 5?-closed elements of I. 

A set E c l'^ is a cr-algebra over M if it contains M and it is closed under complement and countable 
union. Given a cr-algebra X over M, the tuple (M, E) is called a measurable space and the elements of 
S, measurable sets. A set Q c 2*^ is a generator for E if X is the closure of Q. under complement and 
countable union. 

Given a measurable space (M,E), a function // : E ^ is a measure iff - and for any sequence 
{A^,- I / € / c N) of pairwise disjoint measurable sets, ^{[JieiNi) - Z,g/j"(A^;)- The set of all measures on 
(M,S) is denoted by A(M,X). We organize A(M,X) as a measurable space by considering the cr-algebra 
5 generated, for arbitrary 5 € X and r > 0, by the sets F''^ -{jie A(M,X) : yu(5') > r). 

Given two measurable spaces (M,X) and {N,!,'), a mapping f : M ^ N is measurable if for any T e 
l,',f'\T) € X. We use |[M — > A'^l to denote the class of measurable mappings from (M,X) to (A^,X'), 
assuming of course that X and X' are clear from the context. 

Central for this paper is the notion of analytic space that supports some of the main results. As 
properties of analytic spaces are however not used here directly, we only recall the main definitions. For 
detailed discussion on this topic related to Markov processes, the reader is referred to |Pan09l (Section 
7.5) or to IIDob07.1 (Section 4.4). 

A metric space (M, d) is complete if every Cauchy sequence converges in M. A Polish space is the 
topological space underlying a complete metric space with a countable dense subset. An analytic space 
is the image of a Polish space under a continuous function between Polish spaces. 



3 Continuous Markov processes 

In this section we introduce continuous Markov processes (CMPs) BCLMllal ICLMllbl which are 
models of stochastic systems with analytic state space and continuous-time transitions. The defini- 
tion is similar to the one proposed by Desharnais and Panangaden in IIDP03II . but it exploits an equiv- 
alence between the definitions of Harsanyi type spaces IIMV04II and a coalgebraic view of labelled 
Markov processes lldVR99l proved, for instance, by Doberkat in IIDob07l . However, with respect to 
IICLMIIal ICLMIIbn or to fPan09l IDEP021 |Dob07ll . we do not consider action labels. The labels can 
easily be added without changing any aspects of the theory. 

Definition 1 (Continuous Markov processes). Given an analytic set (M,X), where X is the Borel cr- 
algebra generated by the topology, a continuous Markov kernel ( CMK) is a tuple M = (M, X, 9), where 
6 e |[M — > A(M,X)| is the transition function. The set M is the support-set of M denoted supp{M). 
Whenever me M, then (At, m) is a continuous Markov process. 

Notice that is a measurable mapping between (M,X) and (A(M,X), g), where g is the sigma algebra 
on A(M, X) defined in the preliminaries. This condition on 6 is equivalent with the conditions on the 
two- variable rate function used in |Pan091 IDEP021 IDP03II to define continuous Markov processes. 
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3.1 Bisimulation 

Stochastic bisimulation for CMPs follows the line of Larsen-Skou probabilistic bisimulation IILS911 
IDEP021|Pan09l . Recall that EC??) in the next definition denotes the 9^-closed sets of S. 

Definition 2 (Stochastic Bisimulation). Given a CMK M - {M,'L,9) a binary relation 'iiQ MxM is a 
stochastic bisimulation relation if whenever {m,n) € % for any C € S(9?), 



Two processes (yVt, m) and (vVt, n) are stochastic bisimilar, written m n, if they are related by a 
stochastic bisimulation relation. 

Observe that, for any CMK M there exist stochastic bisimulation relations: for instance, the identity 
relation on its support-set is such a relation. The relation ~m is the largest stochastic bisimulation 
relation. 



Definition 3 (Disjoint union). If M = iM,l.,9) and M' = {M' X ,e') are CMKs, then M" = {M"X',e") 
defined by M" - M', X" is the cr-algebra generated Z^y E i±J 2' and 



for arbitrary N el, and N' € Z', is the disjoint union of M and AV denoted by A\" = AV. 

Observe that the disjoint union of CMKs is a CMK. The previous definition allows us to define 
stochastic bisimulation between processes from different CMKs. If m e M and m' e M', we say that 
(M,m) and {M',m') are bisimilar written (At,m) ~ {M',m') whenever m ~m^M' ^' ■ 

3.2 Generators 

The definition of bisimulation can be amended to focus on two particular classes of generators of the 
cr-algebra. 

Definition 4 (Bisimulation Generators). Consider the CMK M = (M, E, 6) and let 



• The bisimulation generator of At, denoted by Gm> i^ the closure of@ under union and intersection. 

• The extended bisimulation generator of M, denoted G/^, is the closure of& under union, intersec- 
tion and complement. 

Observe that the bisimulation generators are generators of i;(~) which is a sub-sigma algebra of S, 
i.e., X(~) is the closure of both Gm and Gm under complement and countable union. This observation 
allows us to characterize the stochastic bisimulation from the perspective of the bisimulation generators 
and to propose some generalizations of the stochastic bisimulation. But more importantly, they will be 
instrumental later, for obtaining our results on logical characterization. 

Theorem 1. Given a CMK M = (M, E, 9), a relation HQ MxM is a stochastic bisimilarity relation iff 
one (or both) of the following equivalent conditions is satisfied. 

• whenever {m,n) e % 9{m){C) = 9{n){C)for any C € G^, 

• whenever {m,n) e % 9{m){C) = 9{n){C)for any C e Gm- 



9{m){C) = 9{n){C). 




= {9{my\[0,r]) \meM,re R+}. 
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4 Continuous Markovian Logics 

In this section we recall the continuous Markovian logic (CML) introduced and studied in BCLMllal 
ICLMllbl . This logic extends the probabilistic logics for discrete-time Markov processes IILS91[|DEP021 
|Pan09l and for Harsanyi type spaces ||FH94[ IZhoOTB to stochastic domains and it characterizes the 
stochastic bisimulation. In addition to the Boolean operators, this logic is endowed with stochastic 
modal operators that approximate the rates of transitions. In the original definition, L^cp is a property of 
a CMP {M, m) whenever the rate of the transition from m to the class of states satisfying cfi is at least r. 

Definition 5 (Syntax). The set £. of formulae of CML is generated by the following grammar, for arbi- 
trary r e Q"*". 

£: 0:-T|-0|0A<^|L,<^. 

As usual, we work with all the Boolean operators, including ± = -iT. In addition, we isolate two 
useful sublanguages of X: 

X+ : i]j:=T\i]j\i]j\ip\/\fj\Lrilj and L~ = {^(j)\(t) e 



4.1 Parameterized Semantics: e-satisfiability 

In HCLM 1 1 a[ ICLM 1 lb ] the first two authors in collaboration with Cardelli defined the semantics of CML 
for arbitrary CMPs, henceforth the classic semantics for CML. We will take a similar approach in this 
paper with the difference that the satisfiability relation is parameterized. Thus, for each rational e > 0, 
we introduce an e-semantics that provides an approximation of the classic semantics. The e-semantics 
can be seen as an "approximation from below" of the classic semantics: while Li-cj) is interpreted at m as 
"the rate of the transitions from m to the class of the states satisfying (p is at least r", in the £-semantics 
it means that "the rate of the transitions from m to the class of the states satisfying (p is at least r-s". In 
this way one can encode observational errors in the logic. Unlike the similar approach of IIDLT08L we 
propose a Boolean semantics. 

Definition 6 (e-Satisfiability). For an arbitrary rational e > 0, the e-satisfiability relation \=sC 5R x X 
defined inductively on the structure ofcp&X,, as follows. 

• m\=i;T always, 

• m\=s ^0 iff it is not the case that m \=e (p, 

• m\=E (pAip iffm \=e (p and m |=g ip, 

• m\=,Lr(Piff9{m)ims) + £>r, 

where f^cpJs = {meW\m |=£ 

Notice that the classic semantics for CML introduced in HCLMlIal ICLMllbll is nothing else but 
0-semantics, since |=o - \=. 

Example 1. Consider the CMK M = {M,2^,6) represented in Figure^ where M = [m,m\,m2,m-i,m4,m^} 
and 9 is defined by the values r,s,s',u€ that label the transition arrow^ We can now understand the 
difference between the classic and the e-semantics. For instance, 

m ^ Ls+s'LuT 

'For simplicity we only represented the transitions with strict positive rates. 
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Figure 1 : A Markov process 

since ~ m4, 6(m)({m2,m4}) — s + s' and m2 N LuT because mj, ~ ms and 0(m2)({m3,m5}) - u. 
Similarly, for some s>0, 

since 6{m){{m2,m4\) = s + s' > (s + s' + E)-sandm2 Ne Lu+sT because 0(m2)({m3,m5}) -u>{u + s)-e. 
On the other hand, 

^ Ls+s'+E^U+s'^ 

since 6(m)({m2,m4}) - s + s' (s + s' + s) and m2 Lu+eT because 6(m2)({m^,m5}) -u'^iu + s). Which 
is exactly the way one may see e as an observational error. 

The semantics of is well defined only if |[0Jg is measurable. This is guaranteed by the fact that 
is a measurable mapping between (M,E) and (A(M,X), g), as proved in the next lemma. 

Lemma 1. For any IcpJs e E. 

We extend the classical metalogical concepts to the parametric metatheory. 

Definition 7. Given a rational e > 0, a formula cp is e-satisfiable if there exists m e supp{Ai) such that 
m \=E (p. We say that (p is £- valid, denoted by |=£ 0, if^cp is not E-satisfiable. 

For notational convenience we will write m^g (p when it is not the case that m |=£ (p, and use |= in 
place of 1=0- The proof of the previous lemma reveals a deeper result connecting the e-semantics, if we 
involve our notion of bisimulation generators. 

Corollary 1. For any rational e > 0, Gm - (Me I <P ^ -C^] and Gm - (E^le I e X}. 

The major advantage that the parametric semantics provides is that one can handle in parallel proper- 
ties from different semantics and, for instance, can prove (e + e')-satisfiabihty properties from properties 
concerning £-satisfiability. 

In what follows we estabhsh a few such results. The first lemma estabhshes the relation between 
e-semantics and the classic semantics. 

Lemma 2. Ifcp e X"*", then for arbitrary e,e' > 0, m |=e implies m ^s+e' particular, m ^ implies 
m |=£ (p. 

The following counter-example shows that we cannot hope for the result to hold for negative formu- 
lae. 

Example 2. Consider the CMKM = ({m},2f'"l,6l) with 9{m){lTj) = r. Clearly m h -'U+sTfor all 6>0. 
Suppose that we also have m |=e -iLr+gT. This is equivalent to m\^ -iLr+^-gT, i.e., ^(m)(|[T]|) <r + 5-E 
for all (5 > 0. This last inequality implies ^(m)(|[T]|) <r-E which contradicts our initial assumption. 
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Notice that if e is growing, the set |[0|e is increasing when cp e £^ and is decreasing when € 
Although negation turns out to be problematic in the case of the previous lemma, we can however 
characterize the relation between \=e and |=e+£' for the entire language. To characterize completely the 
relation between two parametric semantics, we define a pair of dual encodings. 

Definition 8. Let ( >e : X ^ X and {Y : -Lhe two functions on X defined as follows. 

{T}e = T (T)'^ = T 

{Lr(P)s = L,.^^{cp), {L,-(pr = Lr+A4>r 

where r - s = max{0, r-e} 

Observe that for any (f> that is not of type L,-ip with r <E,we have that {{<p)'^)s - {{(l))eY - 4>- 
Before we turn to the main theorem of this section, we apply the previous definition to obtain a result 
on limits. The result may additionally be considered a form of reverse implication for Lemma|2] 

Lemma 3. 7/0 € and for every rational e> 0, m \=e'+e <P, then m |=e' (p. In particular, ifm \=£ (pfor 
all rationals e > 0, then also m\= (f>. 

We are now ready to state the main theorem of this section that establishes the relation between 
various parameterized semantics for the entire language 

Theorem 2. For arbitrary € X, 

1. m \=i;+e' (p iffm |=£ {<p)s', 

2. m\=E4> iffm \=s+s' {(pf' ■ 

From this last theorem we can derive a characterization of the relation between the classic semantics 
and the £-semantics. 

Corollary 2. For arbitrary e X 

1. m\=E(piffm\=((p)s, 

2. m\=(piffm^s{(l>f. 



5 Parameterized Proof Theory: e-Provability 

In this section we extend the metatheory and define a parameterized proof system for our logic that 
corresponds to the parameterized semantics. The parameterized proof system will permit us to prove, 
syntactically, approximated properties of models. We should emphasize that we will not work with 
"approximated proofs", but with "exact proofs" about "approximated properties" and this is where the 
Boolean character of our metatheory plays its role. 

For each rational e > we introduce a notion of e-provability denoted by i-£. Table [T] contains 
a Hilbert-style axiomatization of e-provability for our e-semantics. The axioms and rules, which are 
considered in addition to the axiomatization of classic propositional logic, are stated for propositional 
variables (p,ifj e £. and arbitrary s,reQ^. 

Axiom (Al) guarantees that the rate of any transition with an e- approximation is at least O + e - e; 
this encodes the fact that the real measure of any set cannot be negative. (A2) states that if a rate is at 
least r + s then it is at least r. (A3) and (A4) encode the additive properties of measures for disjoint sets: 
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(Al): he Ls(l> 

(A2): he Lr+s(p L,-<p 

(A3): he Lri4> A lA) A L,(0 A -^l//) Lr^s-e^ 

(A4): he -^Lricp Al//)A -^L,{(p A ^(A) ^ -^Lr+s-s(f> 

(Rl): If he (A then h^LrCp^Lrif 

(R2): {L,<A I r < 5) he L,</. 

(R3): {L,<A I r > 5} he X 

Table 1 : The axiomatization of e-provabiUty for CML 



[[(/> A (Ale and |[(A A -■(Ale are disjoint sets of processes such that |[0 A lAle U |[(^ A -iiAle = I^le- The rule 
(Rl) establishes the monotonicity of L^. In this axiomatic system we have two infinitary rules, (R2) and 
(R3). The first reflects the Archimedian property of rationals: if it is possible a transition from a state 
to a given set of states at any rate r < s, then the rate of the transition is at least s. (R3) eliminates the 
possibility of having transitions at infinite rates. 

Now we can complete the list of parametric meta-concepts initiated in Definition |7] 

Definition 9. A formula (pe £.is e-provable, written he <p, if either it is an instance of an axiom or it can 
be proved from axioms using the proof rules. A formula cp e X,is e-consistent, if(p^l. is not provable. 

Given a set Q X of formulae, we say that O s-proves (p, denoted by O he (p, if(p can be proved from 
axioms and the formulae of<^. O is s-consistent if it is not the case that O he -L. 

For a sublanguage c X, we say that ^ & £,is X'-maximally e-consistent if<S> is s-consistent and 
no formula of can be added to it without making it e-inconsistent. 

The next theorem states that |=e and he agree about the class of CMPs. As before, we will simply 
denote ho by h and we call to it as classic provability. 

Theorem 3 (Soundness and Weak Completeness). The axiomatic system of e-provability is sound and 
complete for the s-semantics, i.e., for any (p& 

l-e (f> iff \=s (p- 

Proof. In IICLMllall we have shown that in table |2] we have a sound and complete axiomatizaion of the 
classic provability for the classic semantics. In other words, we have proved that \- (piS\= (p. 



(Bl) 


hLo0 




(B2) 


h Lr+s(p Lr(p 




(B3) 


h Lr{(p A lA) A Ls{(p A -.(A) 


Lr+s(p 


(B4) 


h ^L,.{(p A (A) A ^Ls{(p A - 


(A) -^Lr+s(p 


(SI) 


If h ^ (A then h LrCp - 


* Lrip 


(S2) 


{L,.(p 1 r < 5) h L,(p 




(S3) 


{L,.<p \ r> s}h Jl 





Table 2: The axiomatic system of classic provability 

Obviously, the axioms (A1)-(A4) are the ( )e-encodings of the axioms (B1)-(B4) and similarly (Rl)- 
(R3) are the encodings of (S1)-(S3). 

Consequently, we obtain that he iff" h (0)e and h iff" he {<py. Now, in the light of Theorem [2] we 
obtain he iff h (0)e iff" \= (0)e iff" Ne 4>- □ 
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Trivial consequences of the completeness theorem, Theorem |2] and Lemma [2] are comprised in the 
next lemma which establishes the relation between various £-provabilities. 

Lemma 4. For arbitrary ^ € X, and rationals e, e' > 0, 

1- !-£+£' W^£ (0>£'/ in particular, hi,(pijfh (0>e. 

2. i-£ (p iffi-E+E' {(pY ; in particular, \- (p ijfh^ {(pY. 

3. If(p& X.'^, he' (f) implies l-£+e' (p. 

The previous lemma allows us to prove a parameterized deduction theorem that establishes the frame 
in which one can use various £-provabilities relations in the same proof. 

Theorem 4 (Parameterized Deduction Theorem). For positive rationals e and e' , and (p e 

1- if^£'+E {(p ^) and \-e' (p, then ^e'+e ^; 
2. if\-E'+E (-"A ^<P) and he' 0, then \-e'+e iA- 

The relation between the classic semantics and the e-semantics also allows us to prove the next 
decidability result. 

Theorem 5 (Decidability and Complexity of e-satisfiability). The problem of deciding if an arbitrary 
property (p e £.is s-satisfiable, i.e., if there exists a CMP m such that m \=e (f>, is decidable in Pspace. 

Following the same proof line of Theorems|3]and|4]we can prove that the logic enjoys a parameterized 
version of finite model property. 

Theorem 6 (Finite model property). Given an arbitrary s-consistent formula e X, there exists a finite 
CMP (M, m) such that m \=e <P- 

6 Behavioral Properties 

In the previous sections we developed the parametric metatheory and prove that it enjoys most of the 
metaproperties of the classic metatheory. In this section we investigate the relationship between this 
parametric logical framework and the behavioral properties of CMPs. We begin by recalling a result 
proved in [CLMUa]. 

Theorem 7 (Logical characterization of bisimulation). Let M - (M, X, r) be a CMK and m, m' e M. The 

following assertions are equivalent. 

L m~ m'; 

2. For any (pe m\= (p iffm' \= (p; 

3. For any (p e m \= (piffm' \= (p. 

Because the encodings ( )e and ( Y preserve the logical implication, a consequence of the fact that 
CML characterizes stochastic bisimulation is the next theorem. 

Theorem 8 (Parameterized characterization of bisimulation). For arbitrary e >0, the following asser- 
tions are equivalent. 

L m~ m' ; 

2. For any (p& m\=E(piffm' \=e (p; 

3. For any (p € X.'^, m |=e cp iffm' \=e (p. 
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However, the interrelations between various £-semantics allow us to prove some stronger results. For 
this, in what follows, we extend the concept of bisimulation towards a notion of e-orders that reflect the 
approximated behaviors. Similar notions have been proposed in literature for less general models. It is 
the case of the point-wise simulation distance defined in IIJS90II for discrete probabilistic systems and 
similarly in IIAHM031 IAFS09II for weighted systems, and for general probabilistic systems in HvBWOll 
lD+041 . 

Recall that for a set C and a relation R, denotes the closure of C to R. 

Definition 10 (e-behavioral orders). Given a CMK M - {M, E, 9), a relation Rc MxM closed under 
bisimulation is 

• an e-behavioral order whenever niRn, implies that for any C € Gyvi, 

e{n){C) - e{m){C^) < s. 

• an essential e-behavioral order whenever mRn, implies that for any C e Gm> 

^(n)(C)-6»(m)(C^)e [0,e]. 

We use <e to denote the largest e-behavioral order and <^ to denote the largest essential E-behavioral 
order. 

Observe that, in the definition of e-behavioural order we can have 9{n){C) < 9{m){C^), while for 
essential e-behavioural order we have always that 9{n){C) > 9{m){C^). Notice also that both and 
are not equivalences and that an essential e-behavioral order is an e-behavioral order, i.e., <^ c -<£. 

Example 3. Figure ^shows three discrete processes with initial states m,n and o respectively. Their 
mutual relationship is easily shown by producing an s-order For simplicity, we have not represented the 
transitions with rate 0. Assuming that s -i- s' - t, we obtain 

R ^ {{m,n)Xmi,ni)Xm,n2),{m,n2),{m,m),Qn5,m)} Q<2e, 

i.e., m <2e n and the value 2e is obtained from 

9{n){C) - 9{m){C'^) = 2s 

for C - {m\,m2,m/[,n\,n2}. Observe in this case that m^ <2e «2 even if the rate of exiting n2 is smaller 
than the rate of exiting m^. But for this reason we do not have m nfor all e' > 0. 
Similarly, we obtain m ofor 

R = {{m,o),{mi,Oi)i=i„5} . 

In other words, the rates of m are at most Is-smaller than the corresponding rates of n, or larger; 
and m has at most s-smaller rates than the corresponding ones ofo, but not larger 

Applying Theorem [T] on bisimulation generators, we obatin the following result, which shows the 
concept of e-behavioral order generalizes the concept of stochastic bisimulation. 

Lemma 5. Any bisimulation relation is an e-behavioral order for any rational e > 0. Moreover, ifm ~ n 
then m<on and n <q m. 

The next theorem generalizes the theorems [7] and [8] for behavioral orders. In this new context the 
e-semantics is the key. 
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Figure 2: Systems demonstrating e-behavioral orders and the significance of stochastic transitions. 

Theorem 9 (Logical characterization of <e). For arbitrary rational e > 0, 

\for any <p e £^,n |= implies m |=g (p] iffm <e n. 

The previous theorem can be further generalized to comprise also the negative formulae. In order to 

do that, because there is an asymmetry between the behavior of the positive and negative formulae in the 
e-semantics, we will need an extra encoding that we define below. This encoding assumes that formulae 
are in disjunctive normal form (when L^^ are considered atoms). 



T 


if 


= T 


J. 


if 


= J. 


LMf\s 


if 


-Lrl// 


-■L^+e|0-|e 


if 


= -^Lrlj/ 


|lAll£'^l<A2l£ 


if 


= 1^1 A 1/^2 


l<Ail£V|iA2l£ 


if 





With this encoding we can state the generalization of the previous theorem. 
Theorem 10 (Logical characterization of <'^). For arbitrary rational e > 0, 



[for any ^ e X,n |= implies m \=s |0|e] iffm <g n. 



7 The pseudometrizable space of processes 

In what follows we use <£ to define a canonical distance between CMPs that resemble (and generaUze) 
the well known point-wise distances for particular types of CMPs such as Markov chains. 

The next result guarantees that between any two systems there is a <s relation for an s that is big 
enough. 

Lemma 6. For any pair of CMPs m and n there exists a positive rational e such that m <e n. 
This lemma allows us to define a function 

J : Mx M — > R"^ by d(m,n) - inf{s \m<sn and n <s m). 

As stated in the next theorem, <i is a pseudometric on M that measures how diff'erent two systems are 
from the point of view of their behavior. The distance between two systems is iff the systems are 
bisimilar. 
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Figure 3: Distances between Markovian processes. 



Theorem 11 (Pseudometric). The function d:MxM- 
characterizes stochastic bisimulation, i.e., 



defined before is a pseudometric on M which 



d{m,n) = iffm ~ n. 

To conclude this section and understand the significance of this distance, we shall take a look at the 
following example. 

Example 4. Consider the CMPs described in Figure^ We notice that the processes with initial states m 
and o are quite similar with respect to structure and rate values; the second one has all the transitions 
E-bigger than the first one. So a first guess will be that d{m, o) - e. But this is not the case because the 
rate of exiting the state m is 

9{m){{mi,m2,mj,m4,m5}) = r+ s + s', 
which is 3e smaller than the rate of exiting the state o 

6{o)({oi, 02,03, 04,05}) = r + s + s' + 3e. 

Consequently, d{m, o) = 3e. 

Consider now the CMPs with m and n as initial states and suppose, as before, that s + s' - t. We 
should notice this time that not all the transitions of the first CMP are bigger than the transitions of 
the second. However, every pair of transitions do not differ with more than e. Since there are paired 
transitions that differ with exactly e value, we obtain that d{m, n) = e. 



8 Conclusions 

In this paper we have introduced a parametric metatheory for Continuous Markovian Logic. The param- 
eter e of the metatheory encodes an observation error that might appear when we analyze a stochastic 
system. We define an e-semantics and an axiomatized e-proof system and we show that the e-provability 
relation is sound and complete with respect to the £-satisfiability relation. This entire logical framework 
also allows us to transfer metaproperties between various e-levels of the metatheory. We prove a series 
of results regarding the connection between e-satisfiability and e + e'-satisfiability and a parameterized 
deduction theorem that combines e-provability and e-i-e' -provability results. 

This classic metalogical framework allows us to give an uniform treatment to all logical proper- 
ties, including the ones involving negative or logical implication, while avoiding unorthodox logical 
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constructs as the real-valued logics. The framework also supports us in identifying two canonical be- 
havioural orders that extend stochastic bisimulation and organize the space of CMPs. These bisimulation 
orders are the cornerstones in the definition of a pseudometric on CMPs that measure the behavioral 
similarity of processes. 

The metalogical framework introduced in this paper can be particularized to more specific Markovian 
models such as the discrete or continuous-time Markov chains. Moreover, the entire development can be 
adapted to specialize on the probabilistic cases, as the mathematical structure that supports the definition 
of CMPs is similar- to the one that supports the definition of labelled Markov processes in the form of 
IIPan09ll . 

This paper opens a series of interesting research questions regarding the relationship between e- 
satisfiability, e-provability and metric semantics. There are many open questions related to the possibility 
of defining a pseudometric over the class of logical formulae that shall measure e-provability; for instance 
such that the distance between <p and if/isOiS <p and ifr are logical equivalent. On this direction we expect 
to be able to prove a version of metric completeness that relates the pseudometric space of CMPs to the 
pseudometric space of logical formulae. The first two authors in collaboration with Prakash Panangaden 
have already obtained a series of results in this direction IILMP12a[ ILMP12bl ; but these results do not 
involve the parametric metatheory yet. The hope is that the new metatheoretical perspective introduced 
in this paper will eventually solve some of the open problems that resisted to the other approaches. 
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